After Russian Hackers Knocked Out a Satellite Network, an AI Tool Is Now Stress-Testing Its Defences
Viasat's satellite network was crippled by a Russian cyberattack in 2022. Now an AI-assisted security tool from Atalanta is being used to check whether the rebuilt defences can hold.

Key points
- Russian hackers attacked Viasat's KA-SAT satellite communications network in February 2022, knocking out internet service for tens of thousands of people across Europe.
- Atalanta's security tool, called Argo, is now being used to test whether Viasat's network can withstand a similar attack.
- Argo uses artificial intelligence to simulate attacks and find weaknesses before real criminals do.
- The exercise is part of a broader push to harden critical communications infrastructure against state-sponsored hacking.
What actually happened to Viasat in 2022?
On the morning Russia invaded Ukraine, a cyberattack wiped out tens of thousands of satellite modems, which are the small hardware boxes that connect homes and businesses to a satellite internet service. The attack hit Viasat's KA-SAT network and knocked out internet access for roughly 30,000 customers in Ukraine and further disruption across Germany, France, Italy and other European countries. Wind turbines in Germany lost their remote-monitoring connections. The U.S. and its allies later attributed the attack to Russian military intelligence.
The method involved malicious software delivered through a misconfigured part of Viasat's network management system, overwriting the modems' internal software and permanently disabling them. Replacement hardware had to be physically shipped to customers. This is not a story about someone changing a password. This is infrastructure destruction.
How does an AI tool help now?
Atalanta's product, called Argo, essentially acts as a tireless digital attacker that the security team controls. It maps out the network, finds paths that a real criminal might take to move from one system to another, and flags the gaps before anyone malicious finds them. The security industry calls this kind of exercise penetration testing, or pen testing, where a trusted party probes a system for weaknesses the way a burglar might case a building.
What AI adds to that process is speed and scale. A human team can test a limited number of paths. An automated tool can test thousands, continuously, as the network changes. SecurityWeek first reported Atalanta's involvement with Viasat.
| Event | Date | Detail |
|---|---|---|
| KA-SAT attack begins | 24 Feb 2022 | Timed with Russia's invasion of Ukraine |
| Modems disabled | Feb 2022 | Roughly 30,000 units across Europe |
| U.S./EU attribution | May 2022 | Blamed on Russian military intelligence (GRU) |
| Argo deployment at Viasat | 2024-2025 | Ongoing resilience testing |
Should ordinary people care about satellite security?
Yes, more than most realise. Satellite networks carry emergency services communications, military logistics, remote hospital connectivity and the internet links that keep wind farms and power grids talking to their operators. When that layer goes dark, the effects land on real people fast.
If you are a Viasat customer, there is nothing specific to do right now. The current exercise is defensive. But it is worth knowing that the equipment sitting on your roof is part of a network that nation-states consider a legitimate military target.
The failure mode here is assuming that rebuilding after an attack is enough. Networks change constantly, and a defence that held last year may have a new gap today. Continuous, automated testing is the operational answer to that problem.
The one-line takeaway: patching the hole that was exploited is step one; proving the rest of the wall still stands is the step most organisations skip.



